You can require all team members to register two-factor authentication (TOTP). When enabled, target members will see a mandatory MFA registration screen on their next login and cannot perform other actions until they register.
For personal two-factor authentication setup, see Two-factor authentication (set up personally). This article covers settings for owners who want to require it for all team members.
Available plans
This feature is available on the Enterprise plan.
Who can configure this
Only users with Owner permission.
Required preparation before enabling (important)
If you enable this without registering MFA yourself as the owner, you will be unable to operate on your next login. Follow these steps in order:
- You as the owner must complete MFA registration by following the Two-factor authentication (personal) steps
- If you log in via SSO, log in once using ID/password authentication and then register your MFA (SSO users cannot register MFA on the Firebase side)
- Enable requiring MFA for all team members in this setting
If you try to enable this while unregistered, the Save button will be disabled. Follow the warning message on screen to prepare.
Configuration steps
- Open "Owner Functions" in the side menu
- Select the "Security" tab and open the "Require two-factor authentication (MFA)" card
- Check "Require team members to use two-factor authentication"
- Read the confirmation text and click "Save"
Behavior after enabling
- Target members will see the MFA registration screen forced on their next login
- They cannot perform other actions until they register
- After registration, they must enter a TOTP code from their authenticator app (Google Authenticator, Microsoft Authenticator, etc.) each time they log in
Users not targeted by design
- SSO users (via Microsoft Entra ID or SAML): Not targeted because MFA is managed on the IdP side
- Email-free accounts: Not targeted because there is no recovery method for TOTP
Set exceptions (make MFA optional for specific groups or users)
After enabling the requirement, you can specify exceptions where MFA is optional. Members of specified groups or individual users will not see a forced MFA registration screen. For example, you can use this to temporarily exclude certain field staff who cannot access an authenticator app.
The exception settings field only appears when the requirement is enabled.
Configuration steps
- Enable "Require two-factor authentication (MFA)" by checking "Require team members to use two-factor authentication"
- Specify exceptions in the exception settings area that appears below
- Exception groups: Select groups you want to exclude (multiple selection allowed). Use this when you want to exclude groups
- Exception users: Select individual users you want to exclude (multiple selection allowed)
- Click "Save"
Behavior when removing an exception
- Users removed from exceptions become subject to the MFA requirement again on their next login
- If they have already registered MFA, they can continue using it
- If unregistered, the registration screen will be forced on their next login
Tips for managing exceptions
- Keep permanent exceptions to a minimum: Exceptions are exceptions to the "all required" baseline. Limit permanent exclusions to cases where you genuinely cannot avoid it for operational reasons — this is safer
- Group multiple users together: If you have many field staff or frequent turnover, create a dedicated group and manage it through exception groups for easier maintenance
- Conduct regular reviews: We recommend reviewing exception assignments quarterly to determine which users or groups can be removed from exceptions
- Exception assignment changes are also recorded in the audit log
Tips for success
- If your operations are SSO-focused, we recommend requiring MFA on the IdP side instead (this centralizes management)
- Notifying your organization before enabling helps reduce support inquiries
- If a member loses access to their authenticator app, they will need individual support from the owner (it helps to establish an MFA recovery process beforehand)